Skip to content

Add SSRF parser and redirect revalidation gates#1705

Open
cuph7022 wants to merge 1 commit into
UnitOneAI:mainfrom
cuph7022:cuph7022-ssrf-url-gates-1702
Open

Add SSRF parser and redirect revalidation gates#1705
cuph7022 wants to merge 1 commit into
UnitOneAI:mainfrom
cuph7022:cuph7022-ssrf-url-gates-1702

Conversation

@cuph7022
Copy link
Copy Markdown

@cuph7022 cuph7022 commented Jun 8, 2026

Summary

  • Add focused SSRF evidence gates for parser consistency, redirect revalidation, DNS/final IP validation, alternate IP encodings, cloud metadata endpoints, and protocol changes.
  • Add SCR-SSRF finding IDs mapped to CWE-918.
  • Extend the output template with an SSRF URL fetch review matrix.
  • Bump secure-code-review to version 1.1.0.

Closes #1702

Validation

  • Reviewed the generated single-file Markdown change.
  • Confirmed the updated skill includes version: "1.1.0" and SCR-SSRF-01 through SCR-SSRF-06.
  • Did not clone, install dependencies, or run project code.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[REVIEW] secure-code-review: add SSRF URL parser and redirect revalidation gates

1 participant